diff options
| author | Julian Andres Klode <julian.klode@canonical.com> | 2024-12-18 19:37:40 +0100 |
|---|---|---|
| committer | Julian Andres Klode <julian.klode@canonical.com> | 2024-12-22 22:55:39 +0100 |
| commit | 90270f0959d490d56db891809d83c91b3d4b9bf0 (patch) | |
| tree | 80589894ae2a0eda080b6c6cf416882b52eaef7d /methods/CMakeLists.txt | |
| parent | 470f5cf449ac20c7d7bf50ad805c72a5f52d256f (diff) | |
hashes, methods: Add OpenSSL backends
Introduce an OpenSSL::Crypto backend for the hashes library
and an OpenSSL::SSL backend for the TLS support in our https
method.
Many thanks to curl for showing the way with how to handle
a CRL file. There are some memory leaks here with the
TlsFd itself as well as the proxy support; and we should
reorganize the code to generate the ssl object as late
as possible.
A peculiar aspect of OpenSSL is that SSL_has_pending() returns
1 even if SSL_read() will fail to read anything and return the
equivalent of EAGAIN. We work around this here by also peeking
ahead 1 byte. I was running a very high RTT connection from
Germany to Australia for testing, and with the peeking it's
using negligible amounts of CPU; before that, it was busy
looping at 100%. Bad OpenSSL!
Diffstat (limited to 'methods/CMakeLists.txt')
| -rw-r--r-- | methods/CMakeLists.txt | 7 |
1 files changed, 5 insertions, 2 deletions
diff --git a/methods/CMakeLists.txt b/methods/CMakeLists.txt index 548d867dc..c27b1438b 100644 --- a/methods/CMakeLists.txt +++ b/methods/CMakeLists.txt @@ -13,14 +13,17 @@ add_executable(http http.cc basehttp.cc $<TARGET_OBJECTS:connectlib>) add_executable(mirror mirror.cc) add_executable(rred rred.cc) -if (HAVE_GNUTLS) +if (WITH_OPENSSL) + target_compile_definitions(connectlib PRIVATE ${OPENSSL_DEFINITIONS}) + target_include_directories(connectlib PRIVATE ${OPENSSL_INCLUDE_DIR}) +elseif (HAVE_GNUTLS) target_compile_definitions(connectlib PRIVATE ${GNUTLS_DEFINITIONS}) target_include_directories(connectlib PRIVATE ${GNUTLS_INCLUDE_DIR}) endif() target_include_directories(http PRIVATE $<$<BOOL:${SYSTEMD_FOUND}>:${SYSTEMD_INCLUDE_DIRS}>) # Additional libraries to link against for networked stuff -target_link_libraries(http $<$<BOOL:${GNUTLS_FOUND}>:${GNUTLS_LIBRARIES}> $<$<BOOL:${SYSTEMD_FOUND}>:${SYSTEMD_LIBRARIES}>) +target_link_libraries(http $<$<BOOL:${WITH_OPENSSL}>:OpenSSL::SSL> $<$<BOOL:${GNUTLS_FOUND}>:${GNUTLS_LIBRARIES}> $<$<BOOL:${SYSTEMD_FOUND}>:${SYSTEMD_LIBRARIES}>) target_link_libraries(rred apt-private) |
